LOCS / Security
Security & Trust Centre

Evaluate the complete private-AI configuration before you trust it

Locs evaluates, governs and records the complete private AI configuration before operational use. This page states the controls in plain language — and the current release status and known limitations, honestly.

01
Controls

Data boundary

Raw enterprise data egress is zero by design. The model, documents and answers stay in your environment; air-gap operation is supported.

Enterprise identity

Provider-neutral OIDC with an Entra profile; role-based access enforced in retrieval queries.

Encryption & keys

AES-256-GCM envelope encryption for raw documents; a key inventory with a lifecycle and raw-master rotation. HSM/TPM/Key Vault are documented integration seams.

Tamper-evident audit

Append-only hash-chained audit trail with security events forwarded to SIEM. Tamper-evident — not WORM.

Prompt-injection & output controls

Deterministic input/output controls and dangerous-action refusal. We measure injection resistance in the Assurance Lab; we do not claim perfect protection or zero hallucinations.

Kill switch & recovery

A kill switch blocks AI serving regardless of state; encrypted backup with verified restore drills preserves audit-chain continuity.

02
Current release status
Production ready for restricted Charging & BSS deployments. This is not a claim of general enterprise production readiness, and not a claim of formal certification.

Known limitations & customer-onboarding validations

The following are validated in the customer environment during onboarding as explicit, fail-closed go-live gates — they are not shipped claims:

ItemStatus
Live Entra login flowOnboarding gate discovery-level validated internally
Live SharePoint / ServiceNow instancesOnboarding gate mock-validated; live per customer
BMC RemedyAdapter only not yet live-validated
Customer HA / failoverOnboarding gate durable queue & reconnect validated; multi-replica failover per customer
Container / OS image scanOnboarding gate dependency scans run; image scan in customer CI
External penetration testPlanned owner-gated
Telecom-SME golden setOnboarding gate synthetic set today; SME-authored per customer
ISO 27001 / ISO 42001 / SOC 2Roadmap readiness targets, not certifications

Full disclosure is maintained in the gap register. Aligned to relevant frameworks; not formally certified.

Ready when you are

Get the CISO & architecture pack.

A complete security package: architecture, data flow, identity, encryption, key management, connectors, assurance, threat model, evidence, recovery, known limitations and customer responsibilities.